SBOM Manager
Software Bill of Materials management. Track all components, licenses, and vulnerabilities across your software supply chain with SPDX and CycloneDX export support.
247
Across all applications
18
Components with known CVEs
12
License types detected
Today
2026-07-31 15:36
Generate SBOM
Dependency Tree
SF.Web (Root)
MudBlazor 7.6.0
Syncfusion.Blazor 33.1.44
Syncfusion.Blazor.Charts
Syncfusion.Blazor.Grids
Microsoft.SemanticKernel 1.44.0
Microsoft.Extensions.Http
System.Text.Json 9.0.2
EF Core 9.0.2
BCrypt.Net-Next 4.0.3
License Distribution
We ship our own signed SBOM
Security Factor 365's release artefacts include a CycloneDX 1.6 SBOM with a detached PKCS#7 signature. Try the verifier with it.
| Version | License | Ecosystem | ||||
|---|---|---|---|---|---|---|
MudBlazor |
7.6.0 | MIT |
None |
Low |
NuGet | |
Syncfusion.Blazor |
33.1.44 | Commercial |
None |
Low |
NuGet | |
Microsoft.SemanticKernel |
1.44.0 | MIT |
None |
Low |
NuGet | |
Microsoft.EntityFrameworkCore |
9.0.2 | MIT |
None |
Low |
NuGet | |
BCrypt.Net-Next |
4.0.3 | MIT |
None |
Low |
NuGet | |
Newtonsoft.Json |
13.0.3 | MIT |
1 CVE(s) |
Medium |
NuGet | |
System.Text.Json |
9.0.2 | MIT |
None |
Low |
NuGet | |
lodash |
4.17.21 | MIT |
2 CVE(s) |
High |
npm | |
axios |
1.6.7 | MIT |
1 CVE(s) |
Medium |
npm | |
express |
4.18.2 | MIT |
None |
Low |
npm | |
log4net |
2.0.15 | Apache-2.0 |
3 CVE(s) |
Critical |
NuGet | |
moment |
2.29.4 | MIT |
1 CVE(s) |
Medium |
npm | |
protobuf-net |
3.2.30 | Apache-2.0 |
None |
Low |
NuGet | |
SharpZipLib |
1.4.2 | MIT |
2 CVE(s) |
High |
NuGet | |
iTextSharp |
5.5.13.3 | AGPL-3.0 |
None |
Medium |
NuGet |